Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The cron template authorizes autonomous modification of core agent context files (AGENTS.md, TOOLS.md, SOUL.md, memory/) based on weekly review output, which expands a learning-review function into persistent behavioral reconfiguration. Because these edits are to high-trust files and are instructed to run silently, reviewed notes can indirectly steer future agent behavior without explicit approval or change review.
